← Back to jobs

Vice President, Security Controls & Compliance

Location
New York, NY
Work type
Full Time · On-site
Posted
2026-08-31

Job description

Role Overview and Core Responsibilities

Define and execute the enterprise cybersecurity governance and compliance strategy, including policies, standards, control frameworks, and operating processes that align with business priorities and risk appetite .
Establish governance processes and metrics that give executive leadership, regulators, and the Audit Committee clear visibility into cyber risk, control effectiveness, compliance posture, audit results, and emerging risks .
Oversee global cybersecurity compliance programs and readiness for regulatory examinations, external assessments, contractual obligations, and requirements including PCI DSS, SOX, NIST CSF, ISO 27001, privacy regulations, and customer security expectations .
Serve as executive sponsor for cybersecurity audits, assessments, and examinations; partner with Internal Audit and business stakeholders to strengthen assurance and drive timely remediation of findings and control deficiencies .
Lead enterprise cyber risk and control assessments, identify gaps, prioritize remediation, and establish accountability mechanisms that support risk reduction and issue closure .
Translate technical security issues into business-focused risk discussions and ensure material cybersecurity risks are appropriately communicated and escalated .
Modernize cyber governance, risk, and compliance capabilities through automation, modern GRC platforms, and AI-enabled processes that improve scale, consistency, and decision support .
Lead and develop a global team responsible for governance, compliance, policy, audit coordination, and control assurance, fostering accountability, transparency, innovation, and operational excellence .
Build strong partnerships across Technology, Product, Legal, Privacy, Risk, Internal Audit, and business functions to address evolving regulatory requirements and enable enterprise-wide change .

Required Knowledge and Experiences

Bachelor's degree in Cybersecurity, Information Technology, Business, Risk Management, or a related field, or equivalent experience and knowledge relevant to leading enterprise cybersecurity governance and compliance .
10+ years of experience in cybersecurity, risk, compliance, governance, or audit leadership roles, with deep knowledge of governance frameworks, regulatory requirements, and control standards .
7+ years of experience leading global teams and large-scale cybersecurity programs across complex organizations .
Experience presenting cybersecurity risk, compliance, and assurance matters to executive leadership, regulators, and board-level committees .
Proven ability to influence senior stakeholders, build cross-functional partnerships, and drive enterprise-wide change initiatives .

Required Technical Skills

Working knowledge of PCI DSS (Payment Card Industry Data Security Standard), SOX (Sarbanes-Oxley Act), NIST CSF (National Institute of Standards and Technology Cybersecurity Framework), and ISO/IEC 27001 .
Experience with cyber GRC (Governance, Risk, and Compliance) platforms used to manage controls, assessments, issues, policies, and compliance obligations .
Ability to develop and interpret key risk indicators, control-effectiveness metrics, executive dashboards, and regulatory or Audit Committee reporting .
Knowledge of automation and AI-enabled governance processes that improve oversight, evidence collection, reporting, and control assurance .

We're also looking for the preferred skills below. Whether you are proficient or could use some brushing up, we're happy to support your career development and growth in:

Financial services or other highly regulated industry experience .
Experience leading cybersecurity compliance programs across multiple regulatory environments and geographies .
Experience implementing modern GRC platforms and AI-enabled governance processes .
Relevant certifications such as CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), CISA (Certified Information Systems Auditor), CRISC (Certified in Risk and Information Systems Control), PCI ISA/QSA, or ISO 27001 Lead Auditor .

Original source